Compared to traditional key management infrastructure (KMI), KMS provides multi-service integration, ease of use, high reliability, and cost-effectiveness — letting you focus on applications rather than cryptographic key management.
Integration with multiple services
Authentication and access control
KMS authenticates every request using AccessKey pairs and integrates with Resource Access Management (RAM) for identity-based and resource-based access policies. Only authorized requests that pass RAM permission checks are accepted. Access control.
Auditing of key usage
KMS integrates with ActionTrail and Simple Log Service (SLS) for visibility into KMS activity. Store usage logs in other services such as Object Storage Service (OSS) for long-term auditing. Use ActionTrail to query KMS event logs. Overview of Simple Log Service for KMS.
Data encryption for integrated services
KMS integrates with Elastic Compute Service (ECS), ApsaraDB RDS, OSS, and other Alibaba Cloud services. Manage your keys in KMS to encrypt data across these services — no complex cryptographic operations required. KMS also protects the native data of integrated services. Understanding KMS integration. KMS-compatible Alibaba Cloud services.
Ease of use
Automatic key rotation: KMS rotates keys automatically, strengthening security while reducing management overhead.
Simple implementation: KMS exposes cryptographic APIs for straightforward encryption and decryption, without requiring knowledge of low-level cryptographic primitives.
Cross-VPC access: Associate multiple VPCs with a single KMS instance to encrypt and decrypt data across VPCs.
Bring Your Own Key (BYOK): Import keys from external systems such as on-premises KMI and use them to encrypt data in Alibaba Cloud services or self-managed applications.
KMS uses compliant key exchange algorithms that prevent operators or third parties from viewing keys in plaintext.
High reliability, availability, and scalability
High reliability
Multi-zone deployment: Prevents single points of failure (SPOFs).
Regular backups: Keys, secrets, and related data are backed up regularly for fast fault recovery.
High availability
Redundant cryptographic computing: Cryptographic computing is distributed across multiple zones with load balancing, achieving a minute-level Recovery Time Objective (RTO).
Dual-zone active-active deployment: KMS instances run active-active across two zones, ensuring high availability and low-latency access from both Alibaba Cloud services and self-managed applications.
High throughput: KMS instances support 2,000 and 4,000 QPS specifications, maintaining service under high concurrency.
Scalability
Upgrade KMS instance specifications as your business grows.
Architecture example
In this dual-zone example, applications run in VPC_1 and VPC_2. The KMS instance is deployed in VPC_1 and associated with VPC_2.
Security and compliance
KMS protects your keys through rigorous security design and strict verification processes.
Exclusive instance: Your keys are managed in a dedicated instance, isolated from other tenants.
Encrypted transmission: KMS uses TLS-only access channels with secure cipher suites, complying with PCI DSS and other security standards.
Certified cryptographic facilities: KMS uses regulator-certified cryptographic facilities. CloudHSM devices hold FIPS 140-2 Level 3 certification. Cloud Hardware Security Module of Alibaba Cloud provides FIPS 140-2 Level 3 compliant HSMs. Integrate KMS with Cloud Hardware Security Module of Alibaba Cloud to use HSM clusters for key management and cryptographic operations. What is Data Encryption Service?
Cost-effectiveness
No hardware investment: No need to purchase, operate, or maintain hardware cryptographic devices.
No HSM cluster deployment: No need to deploy HSM clusters or fund R&D and maintenance of self-managed KMI.
Streamlined data encryption: KMS integrates with other Alibaba Cloud services, eliminating the need to build a data encryption system. Manage your keys, and KMS handles encryption across services.